Samsung Mobile Samsung Pay vulnerabilities
5 known vulnerabilities affecting samsung_mobile/samsung_pay.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4LOW1
Vulnerabilities
Page 1 of 1
CVE-2022-36871MEDIUMCVSS 6.5≥ unspecified, < 5.0.63 for KR and 5.1.47 for Global2022-09-09
CVE-2022-36871 [MEDIUM] CWE-285 CVE-2022-36871: Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for
Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
cvelistv5nvd
CVE-2022-36870MEDIUMCVSS 6.5≥ unspecified, < 5.0.63 for KR and 5.1.47 for Global2022-09-09
CVE-2022-36870 [MEDIUM] CWE-285 CVE-2022-36870: Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to versi
Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
cvelistv5nvd
CVE-2022-36872MEDIUMCVSS 6.5≥ unspecified, < 5.0.63 for KR and 5.1.47 for Global2022-09-09
CVE-2022-36872 [MEDIUM] CWE-285 CVE-2022-36872: Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 fo
Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
cvelistv5nvd
CVE-2021-25525MEDIUMCVSS 6.5≥ -, < 4.0.652021-12-08
CVE-2021-25525 [MEDIUM] CWE-703 CVE-2021-25525: Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to v
Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without user recognition.
cvelistv5nvd
CVE-2021-25527LOWCVSS 3.3≥ -, < 4.1.772021-12-08
CVE-2021-25527 [LOW] CWE-926 CVE-2021-25527: Improper export of Android application components vulnerability in Samsung Pay (India only) prior to
Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.
cvelistv5nvd